CVE Vulnerabilities

CVE-2015-2694

Published: May 25, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a clients request has been validated, which allows remote attackers to bypass an intended preauthentication requirement by providing (1) zero bytes of data or (2) an arbitrary realm name, related to plugins/preauth/otp/main.c and plugins/preauth/pkinit/pkinit_srv.c.

Affected Software

NameVendorStart VersionEnd Version
Kerberos_5Mit1.12 (including)1.12 (including)
Kerberos_5Mit1.12.1 (including)1.12.1 (including)
Kerberos_5Mit1.12.2 (including)1.12.2 (including)
Kerberos_5Mit1.12.3 (including)1.12.3 (including)
Kerberos_5Mit1.13 (including)1.13 (including)
Kerberos_5Mit1.13.1 (including)1.13.1 (including)
Red Hat Enterprise Linux 7RedHatkrb5-0:1.13.2-10.el7*
Krb5Ubuntuesm-infra-legacy/trusty*
Krb5Ubuntutrusty*
Krb5Ubuntutrusty/esm*
Krb5Ubuntuupstream*
Krb5Ubuntuutopic*
Krb5Ubuntuvivid*
Krb5Ubuntuvivid/stable-phone-overlay*
Krb5Ubuntuvivid/ubuntu-core*

References